
CVE-2026-20896-Gitea-Authentication-Bypass
An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

An explanation and PoC to exploit CVE-2026-20896 Authentication Bypass Vulnerability on Gitea. Being able to steal session tokens for valid users in…

Hooked browser communication over MQTT

Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c


CVE-2022-29221 Proof of Concept Code - Smarty RCE

POC For CVE-2020-7693 (Testing on Version [email protected])

CVE-2014-8731 - PHPMemcachedAdmin RCE - Proof of Concept

🛡️ Open-source and cloud-native Web Application Firewall (WAF)

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)


Python script to generate a malicious MP4 file and start a CherryPy web server hosting a simple HTML page with the embedded file. Exploits another…

Automates creation and hosting of a JavaScript XSS payload to install a malicious theme module, triggering a reverse shell via Remote Code Execution…

Remote Code execution in CentOS web panel

The flaw allows an attacker to execute arbitrary system commands on the server hosting the Pterodactyl Panel without any prior authentication.

Exploit script for Apache Struts2 REST Plugin XStream RCE (CVE-2017-9805)